CVE-2025-61481 : RouterOS v.7.14.2 and SwitchOS v.2.18 allows RCE via the HTTP- only WebFig

Sorry, I'm not a native English writer.
If is not understandable, I was trying to confirm what you wrote... on other words :upside_down_face:

It is not something that can be resolved to the satisfaction of those CVE-as-a-hobby writers…

Even when you would use HTTPS, there is still the problem that the device cannot initially have a trusted certificate, and while it would be possible to install one later it would be a risk as well to keep that valid.

HTTP management of newly installed devices like routers is just a fact of life, and it is upon the admin to make sure they are not intercepted during that procedure.

RESOLVED INVALID